Craft a tool call
Action Firewall pipeline
Verdict
—no evaluation yet
atv_id
—
signature (Ed25519)
—
ATV-2080-v1 bands
Index layout (2080-D)
header 0..63
agent_state 64..575
plan 576..1087
tool_call 1088..1471
safety_flags 1472..1727
memory_fp 1728..1863
cost_eff 1864..1879
hw band 1880..2079 (T2 zero)
agent_state 64..575
plan 576..1087
tool_call 1088..1471
safety_flags 1472..1727
memory_fp 1728..1863
cost_eff 1864..1879
hw band 1880..2079 (T2 zero)
Audit chain
Burn-in baseline /burnin-status
Patent §7 5-layer × 4-phase controller. Each layer slot graduates
observation → shadow → assisted → production
gated by samples ≥ 1000, then
TPR≥0.95 / FPR≤0.02 / precision≥0.90, then
override-rate ≤ 5%.
| layer | key | phase | samples | TPR | FPR | precision | override |
|---|
Burn-in attestation /attestation
burn_in_id
—
aegis —
atv —
signature (Ed25519)
—
unverified
AID circuit breaker /admin/aid
Patent §5B per-AID auth + auto-quarantine after repeated violations.
Listed AIDs are hard-blocked
at step 315 until released by an admin token.
Release an AID (admin token required)
Forensic replay /forensic/replay
Patent §13B AES-256-GCM journal. Each call walks every record,
decrypts with the per-tenant data-key, and reconstructs the per-AID
hash chain. Tampered records surface here, not at audit time.
decrypted
—
tampered
—
aids seen
—
Per-AID chain heads
Hierarchical Agent Memory /ham/* — patent §13A
L3+L4 software emulation. Each item is AES-256-GCM encrypted with
AAD bound to (tenant_id|aid|seq). The
cleartext index holds tags + tombstone state only — bodies are
decrypted on recall.
store an item
recall
summarize
ground a claim